This is a horrible day for security.
This is a horrible day for security.
The update system on Chrome is wonderful, in that it just happens. No strange dialog boxes, popup messages or confusing options for the computer-illiterate. It just goes ahead and does it. A power user might not like that, but it is a great system for a huge userbase.
How many insecure ChromeOS devices are there out there? Very few, I'd expect. Not many other operating systems can claim this.
That's damning with faint praise, isn't it? It can, at this point, do MOST of what an everyday Internet user might want? It's that whole 80/20 thing that everyone thought would let somebody overthrow Microsoft Office -- 80% of users only use 20% of the features. Well that's true and all, but it's not the same 20% for everyone, and you only have to miss one feature to make a Chromebook an untenable alternative to a Windows machine. There was a brief window where Chromebooks were significantly cheaper than a comparable Windows laptop but Intel took the ARM threat seriously, Microsoft took the licensing seriously and now the base Chromebook price from a name manufacturer isn't significantly cheaper than the HP Stream or what have you. "Most" is not going to cut it now that the price advantage is gone.
> There are lots of people who are content with its restrictions.
This is really only true in that we live on a planet with many, many lots of people, and so you can find lots of people for which almost anything holds true if you funnel it down. ChromeOS market share is a rounding error at this point, and if there were any signs that this was turning around, Google apparently decided they weren't enough for them to continue.
Having an elderly family member struggle to stay up on Windows is super sad to watch and try to help with. I personally definitely wish that I had been more proactive migrating my grandfather to a more locked-down system when he was slightly younger and had a better capacity to adapt.
If the grandfather really is elderly, like older than 75 or 80, I would push in the direction of asking the question "Does he really need Quicken anyway, or maybe he's at a point where he could give up that responsibility, or compromise with Quicken Online?"
I've never met anyone who said it was, so I doubt it. Stop being a blind advocate and realize that some people do need Windows because they need apps that only run on Windows.
The screen, keyboard, case and battery quality are a joke in most offerings, not to mention most lack dedicated GPUs or specific BIOS features.
Granted, it's not as productive (trackpoint or riot!), but it works.
But with the increasing tivoization of computing? Once below-1000€-laptops/desktops disappear in favour of oversized tablets, how are children going to learn coding? People in developing countries? Poor people in developed countries? Not everyone can afford a 1000€ price tag. Should these people really be excluded from everything that isn't mindless passive consumption?
Simple enough; they'll code on tablets.
I'm actually currently working on a prototype for how a simple, useful development environment might look on a phone or tablet. It's a stack-based concatenative array language with a zoomable user interface. Instead of representing code as lines of text, it takes a more Smalltalk-like approach of a live environment. The benefit of being a concatenative language is that it naturally lends itself to a tree-like format where each word can be viewed and edited on a phone screen. Since semantically it's closer to a weird mashup of J and Perl(!), it can be concise (hopefully still readable) and the vector aspect makes drawing graphics pretty straightforward.
The downside, of course, is that it can be quite hard to reason in. Truthfully, I'm not really sure how to work around that—and I don't think most children will easily think in a function composition/matrix manipulation way. That said, I'd like to find something since I'm fairly sold on the idea that tacit programming with arrays is key to making coding on a tablet work (I think it's fairly clear that imperative or even conventional function languages would be a royal pain to use in such an environment). Maybe something Lisp-like where the user zooms around the AST would be an alternative.
> Poor people in developed countries?
Much cheaper phones and tablets are already vastly more popular than laptops or desktops among poor people. The solution is to move coding forward on mobile, not simply keep rather trashy cheap laptops around.
I see you've chosen well known readable languages as your inspiration ;)
Supermicro XnSAE workstation motherboard: 215
3.3GHz 4 core Xeon E3-1226 CPU w/HDMI out: 217
32 GiB DDR3 1600 ECC Kingston memory: 240
Low end 1/3 w/year for 5 years data center 80GB Intel SATA SSD: 100
Seagate "enterprise" <550/TB/year 4 TB hard disk: 210
982 USD plus shipping plus whatever enclosure, power supply, high quality fans etc. you put into it, which ought not go over $200 new. E.g. after discovering a Lian-Li enclosure I love I bought 3 more and cycle through them.Plus backup, however you do that (make sure critical stuff is offsite!). And, say, a man-week of your time to configure, order, build, install and configure Linux. The result will be very fast and rock solid (well, if put behind a good UPS) workstation class machine with a 5 year design life.
I see at least one clear profit motive for the industry here, let's say you have a "Desktop enabled, smart" smartphone, you'll probably want to buy a dock, screen, keyboard, mouse, productivity software, etc.
The same way we learned since the late 70's on the home computers.
Installing some kind of application that allows coding.
The only difference being that BASIC or Forth were already builtin.
Secure Boot is the best example for that:
• On Windows RT devices it always was mandatory and could not be disabled.
• On Windows 8 devices, manufacturers must give users an option to disable it.
• On Windows 10 devices, it is now in the manufacturer discretion whether it can be disabled or not.
The next step is obvious.
I suppose it's no surprise. It goes something like this: a) underwrite the device (not necessarily lose money on every sale, just lower the margins), b) introduce an app store, c) take a cut of every transaction.
As long as users and developers need your OS, your device - your appstore - you will make money.
There's plenty of free, on-device code editor, compiler/interpreter, etc. apps for Android, including ones that will allow you to run code in the app, or build, package, and install (given that you've enable non-Store installation) Android apps right on the device.
I and many others did learn computing on those systems, so apparently it isn't a show stopper to learn.
I don't remember getting any compiler or interpreter for Amiga, Atari or Apple Mac. You had to pay for them and the schematics were part of the OS SDK, also commercial.
Also going besides the ROM BASIC or Forth meant buying a compiler/interpreter.
The app stores are full of them, just pick one.
AFAIK Arexx was part of Worbench? But yes, you did need to get a compiler/interpreter for that. I thought you were talking about stuff like the C64 generation of computers.
I remember there were GNU tools available for the Amiga, and some magazines came with various development tools -- eg: Blitz Basic. But most were certainly commercial (including Blitz Basic) - but one must consider that even with aminet - there was nothing like the essentially free distribution of today (eg: push to github).
According to this site, Amiga Basic was actually bundled with the machine (note-section: "bundled basic language interpreter (free with machine)"):
http://www.classicamiga.com/content/view/5044/175/
> The app stores are full of them, just pick one.
Did Apple change their policy of allowing development tools? They certainly don't allow the creation of apps on the ipad/iphone as far as I know?
A few of the best ways to learn coding on the move
Codea
https://itunes.apple.com/us/app/codea/id439571171?mt=8
Pythonista
https://itunes.apple.com/us/app/pythonista/id528579881?mt=8
GLSL Studio
https://itunes.apple.com/us/app/glsl-studio/id481421644?mt=8
Lisping
https://itunes.apple.com/us/app/lisping/id512138518?mt=8
There are plenty more, one just needs to search for them.
Also they are pretty cheap compared to what I used to pay for, back in those days.
Much of the use of ChromeOS and ChromeBooks is in education (where they compete with Macs and iPads), where the buyers are not the users, and the restrictions are actually part of the appeal. It's a decent niche I guess, it's just that but when I see some of the newer Chromebooks with Core-i5 processors, I can't but feel it's a waste of horsepower.
I bought my mom a Chromebook and she loves it. I think the group of users who are willing and able to do all their computing tasks inside a browser window is larger than you think.
It's not my "main" computer though, but that was never the problem raised in this thread. The fact is, chromebooks and Chrom{e,ium}OS are very decent platforms for all kinds of users, and they are indeed pretty safe to run. And I often do as others said: I ssh from the chromebook to my other PCs in other rooms, or remote servers, etc...
It's also a great device when travelling if you have a 4G phone providing connectivity or you stop in hotels or conferences with WiFi (I wonder if there's been attempts to bring one to a DefCon or pwn conference to see how it holds... haven't checked).
Sure I find that it hads plenty of shortcomings. But most of them are stuff that are shortcomings for me, professional CS/IT dev/tester/consultant/trainer/teacher/etc... Lots of other user groups will also probably fine shortcomings (like the "elderly" person mentioned requiring Quicken), but it doesn't mean you can't work around the issue (substitute it, use quicken from another machine, etc...).
It surely isn't all-purpose or perfect, but it's still great.
I wholeheartedly agree that I'd be deeply sad to see it sank, way more than I'd have been to see it merged the other way around.
That being said, as recently Android Apps were starting to be available on ChromeOS via the Chrome Web Store and worked decently for the most part, I'm curious to see what the actual integration/folding will be. Because it may be largely marketing-oriented to make Android the prominent part (or just the prominent brand) as it's way more popular in terms of user and device share (billions vs probably a few millions, if even that).
EDIT: And Pichai's quote does not worry me too much until I see something happening: "mobile as a computing paradigm is eventually going to blend with what we think of as desktop today."
In fact, the article seems mostly unsubstantiated, so as long as I don't see an announcement from Google I think I'm not letting go of my chromebook and ChromeOS. :)
Sure, if you say so it must be true.
> How many insecure ChromeOS devices are there out there?
How many ChromeOS devices in absolute numbers are out there and what is the target audience of 200$ laptops?
If I were a hacker, I would certainly not target this platform.
Source: I know lots of people who deploy and manage these in schools.
I made a computer illiterate friend get one because I was sick of doing tech support for his windows Lappie and he loves it, and has had zero probs with it.. the only time he's called me with a problem with it was when he was trying to some fucking exe to win a free ipod. CHROME os rocks.
There's also in-browser VPNing.
It's like driving a little remote control car to the shops and claiming that you went. You didn't.
I could walk into a library and use a terminal there to type code in, but I'm not doing development on that machine - it's just a dumb terminal.
Now I understand the fact that you can remotely connect somewhere else to do work, but the advent of the microcomputer has meant that you shouldn't need to do that. Power usage for the earth will not be great if everyone runs a device that needs power locally, over a network system that needs powered routers, to a computer remotely that needs power just so you can type code in.
That really doesn't make sense.
I agree that in the context of this (sub)thread, it's a bit odd to claim that chromebooks are decent developer workstations, when what's meant is that they're decent dumb terminals. I'd still like to run my code on my dumb terminal - but I think it makes perfect sense to work like that - have something dumb and wireless for human interaction, and data/processing on a dedicated piece of kit. Be that a low power intel cpu and ssd in a small box behind the tv, or something in a rack somewhere.
And the advent of dynamic libraries has meant we shouldn't need Docker, but, well, that's how it is. It's true that in an ideal world we shouldn't need such a mechanism, but in practice this system works very well for me, and the other ones have been frustrating.
I need a working internet connection anyway to do work: I need everything from software updates to GitHub to IM with coworkers to Google and StackOverflow. And the remote machine shouldn't need any more power than my local one. So my added power consumption is just that of my Chromebook, which is about 10 W.
I admit freely that I am not fulfilling the definition of "development on the Chromebook" in a strict sense, but it is certainly a serious answer for how I develop on my Chromebook.
Have you calculated how much it's costing you?
I ended up scripting up a way to find the cheapest Spot Instance price from Amazon for whatever workload I needed - if I was doing builds I wanted the 8 core machines (c4.2xlarge?). They're ~11c an hour as a Spot Instance, although it's 3x the amount for a Windows instance, and I'd be pushed out of the market if everyone started doing this.
I think I was averaging a couple of dollars a day, so I suppose it comes out in favour of using AWS all the time.
(Also if I had a powerful local laptop, I couldn't tell it to do a build, close the lid, and get on the subway without my backpack catching fire. Nor could I have it provide IPv6 to my apartment, host websites behind CloudFlare, provide shells to my friends, etc.)
If I wanted to put some more effort into it, I could certainly do a good fraction of my work (git clone, vi, IRC and email, etc.) on a micro instance. But even a couple of dollars a day would require me to be pretty careful to come out cheaper.
I think my costs would be a bit higher because Kimsufi/OVH/Hetzner are 300-400ms away from me, so the latency is a bit uncomfortable.
When I was in Canada, a Hetzner box was 200ms away and usable, but for ~$30 a month I only had a dual core box - a bit restrictive when doing large builds.
I might have a go at automating setting up a dev environment on AWS which can be torn down when not in use.
Could you share a couple of lines on how you would set that up? Spin up an upstream-provided basic AMI (eg: RedHat/Ubunut/Debian) - and run a few commands under screen via ssh - and then shut it down?
I planned to buy a Chromebook a while ago and do exactly as the parent suggested, but got to the conclusion that it's just not worth the hassle (also, Chromebooks tend to have minimal storage, which is definitely not ideal in a normal laptop).
In general, Chrome OS or not, the HW (touchpad, screen and keyboard even more than raw power) in a 200$ laptop is BAD.
Before Chrome OS, I ran homegrown minimal Linux installations with a separate user account to run Firefox. It was way too much overhead for me to be excited about maintaining, and paying $200 for a secure architecture and security updates by the most competent people in the industry was super attractive. I can do servers very well; I don't also need to do desktops, let alone my personal desktop.
A CrOS-like OS with the ability to run VMs would be pretty great. (And yes, I should check out Qubes.)
I'm all for allowing native applications a place to run, however that doesn't mean that ChromeOS was not able to do anything... both my parents and grandparents are all on ChromeOS laptops now... why? It's all they need, secure and I haven't had to remotely clear out any malware in over a year.
This is pretty much one of the two markets I've ever heard of for ChromeOS machines, the other being education space. What they have in common is that:
1) People want them for SOMEBODY ELSE 2) Because they don't trust that somebody else with the power of a less locked-down machine.
Sure, schools are buying ChromeOS machines... for the students. Not the teachers and administrators. It's too limited of a market segment for ChromeOS to grow a large enough userbase.
They've all been very happy with them... well, one of my grandmothers has trouble with using it sometimes, her hand shakes, but that's a problem with desktops for her too.
I used one for about a year and if I were able to use the VPN to remote into work (stupid proprietary VPN software), I'd probably still be using it... I used remote desktop and SSH to other systems when I needed more for work, but was pretty happy with it. Yes, there were times I needed more, I had a desktop for that... one at work, another at home... most of the time I used my chromebook though.
These days aside from at work, I use my htpc for more web stuff than anything else... I've tried a few android and arm based mini systems for that role, but the experience was less than stellar.. currently an i3-5010u which does pretty well for my general use, and htpc chores. I'm on it right now.
Most people only use/need the web for home use... Chromebooks are great for that... There's even a few halfway decent general purpose email clients being worked on (one client to work over imap, etc for multiple accounts) as opposed to typical webmail. That was about the only shortcoming I really felt. Also, getting my private rsa token for SSH setup on the thing was a little bit of a pain.
Except for an operating system, of course.
http://programmers.stackexchange.com/questions/221615/why-do...
In the end it all runs on an operating system... so it technically falls short of that of course, but building a web-based app is generally easier than raw-coding an application from the OS level.
Nope, it was called Smalltalk.
* chromebooks
* web browsers
* a turing machine implemented by having a grad student a car drive around on a long street
Of course it might be a bit slower, it might take a bit more effort, time and imagination on the part of the user.
But seriously: it needs to run existing programs without recompilation.
That said, while compatibility helps adoption, it is not absolutely necessary. If it were, we would all be stuck with Windows computers in our pockets running on Atom processors having 1:30 hours battery life.
..Or maybe you simply have a deficient imagination?
This is horrible from a usability perspective. Note that large bulk laptop purchasers (schools, large enterprises with mostly web application requirements etc.) have been the biggest markets for chromebook. One of the biggest reasons for that popularity is the lower cost of management of chromebooks compared to windows or mac laptops. In that the base OS not only just works, it also just updates. A huge saving in admin time and headache. The other factor is that all user data is automatically in the cloud, which means backups/restores/replacements/upgrades are trivial operations now.
One way chromebooks can retain this ease of use/administration is by basically shipping a laptop with chrome running on Android OS but no other apps installable by the user (outside of chrome sandbox). This will get Google out of the two OS kernels management business but could still retain the essential goodness of the chromebook concept.
There are quite a few device management solutions out there for Android that can white list, black list, deny all installs of apps. It's very common to setup in business and already completely supported.
It's even far more powerful than that with capabilities to do things like deny certain apps/networks unless you have certain password complexity requirements, etc..
So each app will continue to ask for access to everything and you choose between being info-excluded or giving away your data.
> buy-in from the OEMs to push those patches
How does this work? Is there any legal obligation for manufacturers/vendors to provide these patches in X weeks?
If there isn't then I won't keep my hopes up.
> from moving big parts of the OS to userland so they can be updated separately from the core system
How exactly? By moving from Android to google proprietary apps? If so then this is a two-edged sword as it inevitably binds you to google spyware. Either you own an half-phone or you give away your data.
Sorry if I sound bitter but I see what Android could be and get defeated by what it is.
I never owned an iPhone but my next phone will be one. Maybe I'll still be disappointed, but at least won't have to deal with CM, Xprivacy, manual updates and all the other shenanigans.
Disclaimer: I'm an increasingly disappointed Android user.
I think you might misunderstand what the Marshmallow upgrade will allow. Users will have the ability to turn off any given permission for any given app. Don't want google maps to have GPS access? Cool, just turn it off and the app will have to deal with the lack of information. It's not a Windows model carte blanche per-run thing.
Sure, apps can be abusive and ask for more permissions than they need and refuse to run if they don't have them, but that's a problem with any conceivable permission system.
The OS could give fake data to the apps. Such as a arbitrary GPS location, or an empty contact list.
Famous last words. Take a look at the Android store, it's a wasteland of adware-ridden crap.
If you can't find a calculator app that doesn't require your contacts/GPS, I will personally build one.
Be the change!
Apps under the new model will only ask for permissions when they need it. So, when you decide to post a picture to Facebook, that's when Android asks if you want to give the Facebook app access to your pictures on storage. If you deny it, it lets the app know it doesn't have access. If it's an older app that doesn't understand, it gets fake data as if you had no photos (or no contacts, etc). At least that was my understanding from reading about it.
Note that this security model is similar to web apps wanting to "connect" with you Google account (or Twitter or Facebook for that matter) to access your contacts or similar.
It's disappointing. I saw a Chromebook used by a "normal" person for the first time this week. He loved it. The only benefit for me was the fact you could run Linux in some sense on it, and it was cheap and stealable without too much sadness!
But this merging of browser-OS and insecure Android has signed the death warrant on my devices. Goodbye Samsung and Sony.
When a user has control over updates, the company selling the product carries a relatively low responsibility. When a company does not allow a user to update, then that company carries a much higher responsibility.
If Google provides a security update and a company refuses to update their devices (or allow users to update), then that company has a lot to lose.
The Android ecosystem would be a lot better off if there were a couple large class-action lawsuits with big payouts. Companies really don't care until it hits their bottom line.
I surely won't pay what Google is asking for their devices, given lack of SD card and changeable battery.
Plus, they also proved they aren't trustworthy by not providing a path for those that gave them money for the Nexus with TI processor. As if Google didn't had the money to keep supporting them.
"What about security updates for my phone?" The hurdle is jumped, and the patron has the Google horse land on them, causing death
Goggle has the knowledge and money to do so.
If, as stated in the article, they merge ChromeOS into Android, rather than abandoning ChromeOS in favor of Android (which seems to be how you and many others have interpreted it), they aren't limited to what is currently in Android, since they bring all the capabilities of ChromeOS are now in Android. A merger is functionally equivalent regardless of direction, which just becomes about branding (and its hardly surprising that Android is the more marketable brand.)
And that's pretty much the answer...
BTW, I've found Samsung to be decent with updates as well.
Not really. Android got big because OEMs can do as they like with it. And what OEMs like doing, apparently, is not updating the OS on their device. An Android OS that, from the start, controlled OEMs in some way (by e.g. forcing them to ship updates on a certain schedule) would likely not have become a viable contender in the market.
It's not the fault of Android that OEMs are stupid, but Android was created specifically to cater to OEMs and their stupidity. Android's existence is itself the problem.
(It'd be great if their licensing model up until now was just a bootstrapping strategy, though, and they began requiring things of their OEMs.)
To a certain degree, they're forced to either be open as they are now, or sell devices. Given absurd government rulings, forcing stock Android on OEMs would probably bring an antitrust suit against them.
I'm not sure... From the start, Android was the only viable contender for OEMs. Their choices were create their own OS (good luck catching up to iOS) or take Android with whatever restrictions it had.
As we saw, the established companies wasted years and billions trying to play their same games with customer neglect, pointless restrictions and marketing deals, etc. Android became big precisely because Google was desperate to get into the market and agreed to all of it.
Thank XDA for CM, because otherwise I'd have to get a new phone not for hardware but because the software is unsupported.
Next phone I buy will be a Nexus for this reason.
Just like the Motorola before it, and the Sony before that, and the HTC before that. It's getting tiresome.
My S3 is stuck with 4.3
Personally, I'm not so much upset because Android is uncommonly bad (it's like any other system that gives untrusted users non-root access to Linux: you can probably get away with it, but eh), but because CrOS is uncommonly good.
This is far from true. Android has always had a ton of sandboxing. Every app is its own user, unable to interact arbitrarily with other apps, things like that.
You won't find any desktop OS that comes anywhere close to the security design of Android. But the thorn in Android's security side remains updates, or lack thereof.
> Android's attack surface is much higher than Chrome OS's.
Not really. All you have to do in CrOS is compromise Chrome (which has happened plenty of times), and you have owned the user. You've won. Game over. And Chrome's attack surface is huge, just like any other browser's. The kernel syscall interface is relatively tiny, and SELinux clamps that down even further.
Doesn't seem correct: https://source.android.com/devices/tech/security/overview/ke...
Lenovo, Samsung, Apple and Google are all in complete control of the devices they sell: they all control hardware, software and services themselves.
If the software is based on Android or not has nothing to do with how often these devices get updates.
Desktop OSes are generally pretty bad. Unsandboxed Windows and OS X apps can do an awful lot with your computer.
I really like that Apple and Microsoft are pushing for sandbox models in their OSes.
Of course there are things like HP-UX safes, Tru64 and Solaris trusted zones.
None of them are POSIX.
Besides the average user would not even know where to start.
You can use VMs for some of that, but that's the limit on sharing (and that's if you trust your hypervisor to be a separation kernel thing; reasonable for many people. Not for others.) Docker/containers isn't enough. Users aren't enough. Processes aren't enough.
With Microsoft producing a laptop of their own that starts at $1499, I think all we can really say is "Apple doesn't produce bargain laptops".
Typically not in the segment where they compete (high-end laptops). However, the cheapest MacBook (in Germany) is 999 Euro. A large chunk of the market cannot afford or does not want to spend 999 Euro on a laptop. If you only want to e-mail, upload/view some photos, make a spreadsheet, a 999 Euro MacBook is expensive compared to a 200 Euro Chromebook or 300 Euro Windows laptop.
The complicating factor, and why it's such an enduring belief, is that Apple doesn't ship adware and has minimal hardware standards which are higher than the lowest-end PC market. You see this over and over again where someone is either unable to back up claims or, when pressed, has to admit that the $400 notebook they said was “just like” the MacBook Air had a previous generation processor, magnetic hard drive instead of SSD, low-contrast/dim display, mushy keyboard or unusable trackpad, etc. The same manufacturer probably even makes something fairly competitive, too, but it costs about as much.
Apple has nothing for the average home user who wants a $199-$399 laptop. Or even for the geek or gamer who wants a reasonably-priced tower.
It's about half the market as far as profit goes – the low-end stuff is absurdly low margin and customers have very little brand loyalty.
More importantly, the netbook and other low-end market has been fading as people buy tablets and large smartphones. It's not at crossover yet but there's a growing percentage of people who don't have a traditional computer at all and that's going to eat into the low-end market most heavily because the difference in utility between a $200 netbook and a $200 tablet is the smallest and hardware quality is often better on the tablet side.
The demographic shift is somewhat fascinating, with PC ownership declining by 10% for people under 30 in the last 5 years:
“Today, 78% of adults under 30 own a laptop or desktop computer, compared with 88% who did so in 2010. Smartphone ownership, on the other hand, has surpassed both of these devices, with 86% of 18- to 29-year-olds owning one in 2015.”
http://www.pewinternet.org/2015/10/29/technology-device-owne...
Yes, that's true. But Apple needs to have a high profit margin because it only makes $1 billion a week (after tax) and has only $200 billion in the bank. It would obviously be a waste of money to serve more people, or even pay its Chinese workers a living wage.
More importantly, the netbook and other low-end market has been fading as people buy tablets and large smartphones.
The netbook market hasn't existed for a very long time, but sales of $199 laptops like the HP Stream 11 seem to be pretty good. Obviously they don't include the ability to overcharge users by $100 a shot for small increases in RAM or storage.
However, the tablet market -- including iPads -- is declining faster than the PC market. Nowadays even Apple has followed Samsung etc in making phablets.
They do. Compare the workers at Foxconn Apple factories to other factory workers. And remember that just about every other tech company also makes their stuff in China.
It was Apple production lines that were driving suicides, and hence the nets round Foxconn dorms.
Pegatron has had Chinese workers doing 90-100 hours a week, sometimes more, just so Apple fanboys can get their fancy new toys without the massive loss of kudos that waiting a month would cost them. http://www.chinalaborwatch.org/report/107
And Apple workers do not get a living wage, according to China Labor Watch, even though -- as I stated correctly -- Apple is making a billion dollars a week in profits and has more than $200 billion in cash.
Of course, this isn't brutal capitalist exploitation.
Or if it is, well, who cares?
I think for directly comparable hardware its not much more expensive, but:
1) the entry price is higher -- to get a minimally functional Apple laptop or desktop you're paying more than any of the alternatives.
2) the smaller number of Apple models compared to any major PC maker (much less the union of all PC makers) means that, unless your hardware preferences happen to match perfectly to an Apple model, you're often able to find a PC that matches your preferences less expensively simply because you are unlikely to have to overshoot your target as far as with Apple.
Minimum wage before taxes - 505 €
Average PC price at a retail store - 400 €
Windows has a huge lock-in for the business world due to compatibility, and a few other niches like high-end gaming for similar reasons. Without API compatibility that's a really tough space to get into.
It's quite believable that Android/ChromeOS will take over the netbook market by being cheaper than Windows, and the premium personal market – which is where most of the profit is – if they can get quality hardware shipping at prices competitive enough to make up for the lack of applications (almost all Android apps will need some sort of UI modifications) but it really doesn't seem like they'll get anywhere in the business world. Cracking that means either convincing everyone to drop legacy apps for web apps or remote clients (how many more decades?) or offering API compatibility (invest heavily in WINE?) — otherwise, the cost of a Windows license isn't that much (especially with 10) and certainly not enough to push someone towards the most limited option.
Every store I visit the cheapest laptop-like devices are windows 10 devices, 20-30$ cheaper than chrome os devices. Android ones certainly exist, but only start at roughly double the price of cheap windows 10 machines.
Those windows 10 machines aren't even bad. If you need office + browser they work pretty well.
Just checking today on Amazon:
Cheapest chromebook: 161.99 (and that's the Asus C201, as in STAY AWAY). Cheapest vaguely reasonable chromebook ~210
Cheapest windows 10 laptop: 164.89. This one is actually usable. Screen resolution being the biggest minus point.
Cheapest android "laptop": 165, and this is not something you want. Cheapest one you do want: ~$300. There are cheaper android laptops, but they're chinese duplicates you do not want.
Outside of the US, windows 10 laptops win by a mug bigger margin.
I think if Google continues to be willing to subsidize Android development at a loss to maintain marketshare, that could change if Microsoft isn't willing to lower the price for a consumer copy of Windows to zero. Anyone who remembers the 90s knows that Microsoft is unlikely to make it that easy.
To drop good apps for web apps.
Also, was there a reason you started referring to specific versions of OS's like Windows 10 and BB OS 10 and then disrespectfully mentioned Android without a version number? Don't you think that was a bit disingenuous, and lame, of you to start mentioning specific OS versions and leave out Android? If you're going to use version numbers then shouldn't you have applied them to all of the OS's you mentioned instead of cherry picking OS versions and then shitting out the line "And then there's Android" at the end?
Android marshmallow = exceptionally bad.
BB10 is a fundamentally different OS (QNX based) than pre-BB10. but Pre-10 was also a good OS from a security perspective, just utter shit to develop meaningful third party apps for.
Windows...used to be horrible. Big changes around Vista (although, ~unusable). Since Windows 7, it's been "reasonable" in a highly managed corporate environment, and not bad even out of the box. 8, 8.1, and 10 have been improvements on that. It's actually easier to do a 10k user highly locked down Windows deployment (although expensive, and involving a lot of experts and third-party tools) than to do a 10k user locked down Mac OS X deployment. Apple had a lot of advantages by starting from UNIX and from basically starting after security was a "thing", but hasn't done as good a job on OS X security as I'd like. iOS, on the other hand, is amazing -- the only serious deficiencies I find with iOS are a lack of "enterprise as sole root of trust" (which no one does, with the possible exception of (Blackberry Pre-10 and post-10), or roll-your-own open source linux/bsd with a lot of trusted computing grafted on in ways which are not at all trivial to do), and a lack of emphasis on anti-forensics on the device itself -- if you unlock it, it contains an sqllite db with ~every message, which shouldn't be how they do it.
OTOH, on cloud services, Google is far and away superior to Apple. The biggest problem with Apple is you're largely pushed toward iCloud which is not amazing from a security perspective. The true win of ChromeOS was you were equally pushed to the Google ecosystem, which is amazing for cloud service security -- the sole problem being you're 100% exposed to Google, Inc. which is both a US company and a single third-party entity, but if you had to pick a single company to be responsible for your cloud services security, you'd probably pick Google on the merits.
Additionally, Android patches are distributed pretty fast by Google to their phones. It's unfortunate that the OEM's and carriers delay the process for their phones, but Google has no current control over this.
Someone else expounded earlier: "On Android, questionable apps have direct access to the entire kernel system call interface, as well as to other OS features. Personally, I'm not so much upset because Android is uncommonly bad (it's like any other system that gives untrusted users non-root access to Linux: you can probably get away with it, but eh), but because CrOS is uncommonly good."
I don't think it's reasonable to ask for pointers on how to root an Android device in a public forum, and the size of the attack surface seems to me like a rather reasonable measure of a system's security.
As for the size of the attack surface being a factor - I agree, but with the exception of QNX and its microkernel (which has issues of its own) pretty much every other monolithic kernel based OS also has a large attack surface so I'm not exactly sure what point you're trying to make other than the obvious.
>Personally, I'm not so much upset because Android is uncommonly bad (it's like any other system that gives untrusted users non-root access to Linux: you can probably get away with it, but eh), but because CrOS is uncommonly good."
Chrome does have great sandboxing, but don't disparage Android just because it works like 99% of the other OS's out there. And I wouldn't be surprised if Android inherits some of Chrome's sandboxing tech when the two merge because I think it's pretty much inevitable that it will.
Alright, as something of an Android fanboy it pains me to admit, he probably has a point in this case. But it'd be nice to hear about what specifically is wrong, especially since it would seem there's a fair bit right, like SELinux, automatic encryption, ASLR. The worst thing in my view, is the permissions system, which is probably salvageable (and as I understand it, was improved in Marshmallow.) 'rdl has given more details about pretty much every imaginable system but Android -- are we supposed to just assume Android does every bad thing he mentioned, and the opposite of every good thing?
Edit: I could almost let this slide since the particular counter-comment was equally vacuous. It's still annoying to see "security guy from $BIG_CO => GTFO" (who is apparently smarter than all the security people at Google who've worked on Android, but we just have to take your word for it since you didn't elaborate.)
This. It's not just "close to" appealing to authority, it's straight up appealing to authority. And yes, it's a common practice in the infosec community. The whole security industry is built on a reputation system. It pays to remember that the number of exploits and vulnerabilities etc. in commonly used software that are reported on practically a daily basis came out of the same reputation based system.
Geofft expounds some more: On Android, questionable apps have direct access to the entire kernel system call interface, as well as to other OS features. Personally, I'm not so much upset because Android is uncommonly bad (it's like any other system that gives untrusted users non-root access to Linux: you can probably get away with it, but eh), but because CrOS is uncommonly good.
I'm not sure if these are related, nor how iOS avoids it. The answer is probably in here: https://www.apple.com/business/docs/iOS_Security_Guide.pdf
FWIW, I've heard Googlers familiar with it refer to Android as a pile of crap, as well.
Android's security indeed relies on UNIX's (filesystem permissions, separate UIDs for each app), but he praised OSX and iOS (I think) for starting from UNIX[0], so it would be inconsistent to also damn Android for it (which I don't think he necessarily did, since dissing UNIX security was in a different context.) From skimming the iOS security guide (and having no iOS dev experience) it looks like it's similar: "The majority of iOS runs as the non-privileged user “mobile,” as do all third-party apps" -- although being BSDish vs Android's Linux could mean that's quite different.
> On Android, questionable apps have direct access to the entire kernel system call interface, as well as to other OS features... because CrOS is uncommonly good.
So CrOS has the advantage because I guess it does not allow running untrusted native code at all, containing things entirely in interpreted/JIT'd VMs. That would be a good point... except every other OS 'rdl esteems higher than Android (Windows, OSX, iOS, Blackberry) probably also runs native code with full access to syscalls (making some assumptions here, but I think it's reasonable that to whatever extent 'geofft's statement about Android is true, it applies fairly uniformly to the rest.) So, why are they good or even just OK, but Android is horribad?
I'm not sure I'm actually addressing arguments 'rdl would have made about Android -- but that's the point, he didn't really say anything that can be argued!
> FWIW, I've heard Googlers familiar with it refer to Android as a pile of crap, as well.
Yeah, it's probably true -- I wasn't saying "Google made it, so it must be good", but underlining the fallacy in relying on a prestigious company association as proof of merit. Android probably didn't have the best talent when it started in 2003 and is now painted into a corner of backwards-compatibility and a huge codebase that would be risky to revamp all at once. I guess my favorite aspect of Android is really just that it's open-source-ish and has enough critical mass to be useful (as opposed to Firefox OS and Ubuntu at the moment) -- so if ChromiumOS were to become the new AOSP as some are speculating, sounds good to me.
A) its BSD (Torvalds have offended a sizable part of the -sec community by not highlighting security updates in release notes)
B) it is locked down by default, to the point that there is not even a common storage area for files (this "blew up" in Android a while back because some big name messaging app was dumb enough to put unencrypted user data in exactly such a common area).
The comparison between Android and iOS is especially curious, in part because it's such a competitive space, and also because rdl's opinions varied so extremely.
Both OS X and iOS are based on Darwin, which also suggests vulnerabilities in kernel calls are not what rdl had in mind. When his latest startup was acquired, the blog post [1] described a part of it as:
> Beyond the company’s work in VPNs, CryptoSeal applied Trusted Computing technology to commodity servers, protecting them from compromise by outsider attackers or insider subversion, and guaranteeing the integrity of server-side applications to remote end users.
Perhaps something about the hardware iOS runs on is what impressed him so?
1. https://blog.cloudflare.com/cloudflare-acquires-cryptoseal/
Have you see the CVE iOS database? If "Android is a pile of crap" then I can only imagine what iOS must be.
iOS: 749 Vulnerabilities http://www.cvedetails.com/product/15556/Apple-Iphone-Os.html...
Android: 138 Vulnerabilities http://www.cvedetails.com/product/19997/Google-Android.html?...
The he can give reasons about his comments.
until now, they sound just like hatred and nothing more.
Appealing to authority is always a bad thing without any arguments backing the claims
Or perhaps advice given based on non-public information.